MS-102 Deploy and manage a Microsoft 365 tenant Practice Question
You are the Microsoft 365 administrator for a company that uses Microsoft 365 E5. The company has a hybrid identity environment with Microsoft Entra Connect Sync. You need to implement Microsoft Entra Password Protection to prevent users from using weak passwords. You must ensure that the on-premises Active Directory Domain Services (AD DS) environment enforces the same password policies as Microsoft Entra ID. What should you do? (Choose two.)
⚠ Common exam trap
The trap here is assuming that password hash synchronization is required or that the proxy service should be installed on a domain controller, which are common misconceptions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Install the Microsoft Entra Password Protection proxy service on a server in the on-premises network.
To enforce Microsoft Entra Password Protection on-premises, you must deploy both the proxy service and the DC agent. The proxy service enables communication with Microsoft Entra ID to retrieve the password policies, and the DC agent on each domain controller enforces those policies during password changes. Password hash synchronization is not required, and the proxy service must not be installed on a domain controller. These two components work together to extend Microsoft Entra Password Protection to the on-premises AD DS environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Install the Microsoft Entra Password Protection proxy service on a server in the on-premises network.
Why this is correct
The Microsoft Entra Password Protection proxy service is required to enable on-premises domain controllers to communicate with Microsoft Entra ID for password policy enforcement. The proxy service acts as a bridge between the on-premises environment and Microsoft Entra ID, forwarding password validation requests. Without the proxy, the domain controllers cannot access the global banned password list or custom banned lists. This component is essential for the on-premises enforcement of Microsoft Entra Password Protection.
- ✗
Enable password hash synchronization in Microsoft Entra Connect.
Why it's wrong here
Password hash synchronization is not required for Microsoft Entra Password Protection. Password hash synchronization synchronizes password hashes from on-premises AD DS to Microsoft Entra ID for authentication, but it does not enforce password policies on-premises. Microsoft Entra Password Protection works independently of password hash synchronization and can be used with or without it. Enabling password hash synchronization would not help meet the requirement to enforce the same password policies on-premises.
- ✗
Configure the on-premises domain controllers to use the Microsoft Entra Password Protection proxy service as a forwarder.
Why it's wrong here
The proxy service is not configured as a forwarder on domain controllers. Instead, the DC agent on each domain controller communicates with the proxy service to retrieve password policies. The proxy service is installed on a member server, not on domain controllers, and it does not act as a DNS or authentication forwarder. Configuring domain controllers to use the proxy as a forwarder is not a supported configuration and would not enable password protection.
- ✗
Install the Microsoft Entra Password Protection proxy service on a domain controller.
Why it's wrong here
The proxy service should not be installed on a domain controller. It is recommended to install the proxy service on a member server that is not a domain controller to avoid performance and security issues. The proxy service requires network access to Microsoft Entra ID and should be isolated from the domain controller role. Installing it on a domain controller could introduce unnecessary overhead and potential security risks, and it is not a supported best practice.
- ✓
Install the Microsoft Entra Password Protection DC agent on all domain controllers.
Why this is correct
The Microsoft Entra Password Protection DC agent must be installed on each domain controller to enforce the password policy. The DC agent receives password policy from the proxy service and applies it during password changes. It also caches the policy locally so that if the proxy is unavailable, the domain controllers can still enforce the last known policy. Installing the DC agent on all domain controllers ensures consistent enforcement across the domain.
Go deeper
Related to this question
Learn chapter
Microsoft Entra Verified ID
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Microsoft Entra Connect
Microsoft Entra Connect is a tool that synchronizes on-premises Active Directory identities with Microsoft Entra ID (formerly Azure AD) to enable single sign-on and centralized identity management.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.